Threat intelligence feed
Malicious Domain Feed
High-fidelity C2, malware-distribution and phishing domain intelligence tied to active campaigns, updated hourly. Every indicator is attributed to a specific family, framework or campaign so your team knows what it's blocking.
15-day free trial · no credit card · reply within one business day
Drops straight into the tools your SOC already runs
Built for action, not volume
Block the infrastructure behind active campaigns
Most domain feeds prioritize coverage over confidence. The Malicious Domain Feed is different: a tighter set of C2 and distribution domains tied to live campaigns, each attributed to a specific family or framework. You get indicators you can act on immediately, without spending analyst time validating whether a domain is actually malicious.
C2 and campaign-tied coverage
Focused on command-and-control, malware-distribution and phishing domains in active use. You get a curated view of the infrastructure threat actors are operating right now, not a broad list padded with stale or unverified domains.
Attribution on every indicator
Every domain is attributed to a malware family or C2 framework. A blocked request tells you whether you're looking at a Cobalt Strike C2, an infostealer distribution chain, or ransomware staging infrastructure.
Flexible delivery, no new tooling
Consume the feed as CSV, REST API, STIX/TAXII or MISP. Push domains directly into FortiGate NGFW as an external threat feed, or into any SIEM, TIP or MSSP workflow without a new ingestion pipeline.
The Malicious Domain Feed focuses on the infrastructure threat actors are actively using: C2 endpoints, malware-distribution domains and phishing infrastructure tied to live campaigns. When a domain hits your blocklist, it’s because it’s in active use, not because it appeared in a passive collection months ago.
Every domain is attributed to a malware family or C2 framework. A blocked request doesn’t just generate an alert. It tells you whether you’re looking at a Cobalt Strike C2, a Lokibot distribution chain, or ransomware staging infrastructure.
You get targeted domain coverage that works alongside broader blocklists: fewer indicators, higher confidence, and the campaign context your analysts need to triage and respond.
What’s in the feed
- Hourly-updated C2, malware-distribution and phishing domains tied to active campaigns
- Family and framework attribution on every indicator, including Cobalt Strike, Lokibot and Nanocore
- Coverage across dozens of malware, infostealer, RAT and loader families
- CSV and REST API (JSON) delivery for bulk ingestion and automation
- Available through STIX/TAXII and MISP feeds for teams standardizing on threat-intelligence platforms
- Ready for FortiGate external threat feeds and any DNS or firewall blocking workflow
Evaluate before you commit
You can validate freshness, attribution quality and feed fit against your existing stack before committing. Test domain indicators against your Microsoft Sentinel incidents, populate MISP events, or compare coverage overlap with your current sources to understand where this feed adds signal.
Start a 15-day free trial. Access is immediate and includes the full PrecisionSec feed set: Malicious Domain Feed, malware domain list, malicious IP, URL and hash feeds.
When to use this feed
- SOC alert enrichment: pivot from a domain hit to campaign context and family attribution so analysts know what they’re dealing with before escalation.
- FortiGate and firewall blocking: push high-confidence C2 and distribution domains directly into FortiGate NGFW, or into any DNS or SIEM control in the path of user traffic.
- Threat hunting: use attributed domain indicators to search for related campaign infrastructure across current and historical logs.
- MSSP and multi-tenant coverage: add curated C2 and distribution domain intelligence across customer environments with a predictable feed format.
- Data resellers and security products: integrate high-confidence malicious domain intelligence into your own platform without building a collection pipeline.
You get the Malicious Domain Feed with every PrecisionSec intelligence subscription, alongside malware domain list, malicious IP, URL and hash feeds. Request evaluation access to see live data, delivery formats and integration options.
Ready to see all of our data?
Start your 15-day free trial and get the full Malicious Domain Feed feed, plus every other malware and C2 feed.